Hover — Privacy Policy
Last updated: 26 August 2026
Hover is a browser extension that lets you trade tokens directly from X (Twitter). This policy explains exactly what the extension does and does not do with your information.
The short version: Hover has no accounts and never has access to your private keys or seed phrase. Your settings and swap history live on your own device. Two things reach our own backend, both described in section 3: anonymous usage counts (a random install id — never a wallet address), and, because Hover Points are certified against the blockchain, the public wallet address and transaction hash of swaps made through Hover. Trades you explicitly publish with the Share button upload the share card to render its public link page.
1. We never have access to your keys or your funds
Hover is non-custodial. It cannot hold, move, or spend your assets.
- Hover never asks for, receives, stores, or transmits a private key, seed phrase, or recovery phrase. There is no code path in the extension capable of doing so.
- Every transaction is built by a third-party router (Jupiter on Solana, LI.FI on EVM chains) and must be signed by you in your own wallet. Your wallet's confirmation screen is the only thing that authorises a transaction.
- Hover cannot initiate a transfer, move funds, or trade on your behalf.
2. What is stored on your device
Hover stores the following locally, using your browser's extension storage. It stays on your device and is not transmitted to us.
| Stored | What it is |
|---|---|
| Connected wallet addresses | The public address and wallet name (e.g. "Phantom") of wallets you connect. Public addresses only — never keys. |
| Swap history | Your Hover trades: tokens, amounts, transaction hashes, chain, timestamp, status. |
| Holdings preferences | How your positions are ordered, which ones you chose to hide, and small positions you chose to show anyway. |
| Settings | Slippage tolerance, quick-buy amounts, quick-sell percentages, on/off state. |
Settings and preset amounts use Chrome's synced extension storage, so they follow your Chrome profile across your own signed-in browsers. That syncing is performed by your browser, not by us.
You can erase all of it at any time by removing the extension, which deletes its storage.
3. What leaves your browser, and to whom
Most of what Hover fetches goes directly from your browser to the third-party services below; we do not receive copies of those requests. What our own backend receives is limited to the items marked "our backend" in this section — anonymous usage counts, leaderboard certification, ticker resolution, tips lookups, and shares you explicitly publish.
Market and token data — token addresses, tickers, and chain identifiers are sent so prices, charts, and token details can be returned:
- Jupiter (
api.jup.ag,lite-api.jup.ag) — Solana prices, token search, routing, safety screening - LI.FI (
li.quest) — EVM prices and routing - Dexscreener (
api.dexscreener.com) — prices, token images, market data - GeckoTerminal (
api.geckoterminal.com) — charts - pump.fun (
frontend-api-v3.pump.fun) — launch status, for pump.fun-launched tokens only
Blockchain reads — your public wallet address is sent to read balances, list your holdings, and confirm transactions. Because Hover supports ten chains, a single balance refresh may contact several of these at once:
- Public RPC nodes:
*.publicnode.com,*.drpc.org,mainnet.base.org,arb1.arbitrum.io,mainnet.optimism.io,bsc-dataseed.binance.org,api.avax.network,api.mainnet.abs.xyz,rpc.mainnet.chain.robinhood.com,api.mainnet-beta.solana.com - Block explorers, to list the tokens you hold:
*.blockscout.com(Ethereum, Base, Arbitrum, Polygon and Robinhood Chain explorers) andexplorer.optimism.io
Building a trade — when you request a quote, your public wallet address is sent to the router (Jupiter or LI.FI) because a signable transaction must be addressed to you. Jupiter also receives it when Hover refreshes your Solana balances. No key material is involved.
Safety screening — when a token is screened, its contract address (not your address) is sent to GoPlus (api.gopluslabs.io) and RugCheck (api.rugcheck.xyz).
Name lookups — when displaying a .sol or .eth name, the relevant address or name is sent to Bonfida (sns-api.bonfida.com, sns-sdk-proxy.bonfida.workers.dev) or ENS Ideas (api.ensideas.com).
Anonymous usage counts (our backend) — so we can answer "how many installs, how many swaps" without accounts, the extension sends our backend an event when it is first installed and when a swap confirms. A swap event carries a random per-install identifier, the chain, the token ticker, the trade direction, and a rounded USD amount. It never carries your wallet address, transaction hash, or any account identity; the identifier is generated on your device, is linked to nothing else, and resets if you clear the extension's storage.
Hover Points and the leaderboard (our backend) — Hover Points belong to a wallet and are certified against the blockchain rather than taken on trust. When a swap you made through Hover confirms, the extension sends our backend your public wallet address, the chain, the transaction hash, and — if you left the credit checkbox ticked — the X handle of the post that surfaced the token, so the swap can be verified on-chain and credited. These are public facts already visible on the blockchain; we never receive keys and cannot move funds. Wallets with points appear on the public leaderboard by address, and your address is sent when the extension asks for your own rank. Reads for the live board, ticker resolution ("cashtags") and remote configuration carry no identity.
Tips feature (our backend) — if you use tipping, the X handle you are tipping is sent to our backend to look up an associated public address. We do not store a record of who tipped whom.
Sharing a trade — sharing is entirely optional and happens only when you press Share on a completed trade. Nothing is ever uploaded for trades you don't share. When you do share, Hover publishes to our backend:
- an image of the share card you saw on screen, and
- the details printed on it: token symbol and name, chain, the amount you received, what you spent, the price, your Hover Points for the trade — and, if you leave the credit checkbox ticked, the X handle of the post's author ("found via @…").
These exist to render the public link page your post carries, so they are publicly readable and effectively permanent — that is what a share is.
A trade share does not carry your wallet address. A rank share — the card showing your leaderboard standing — does: your public wallet address is printed on the card itself, because the rank it displays belongs to that wallet. Your leaderboard standing is public by address in any case, so a rank share can be traced back to the wallet that published it. Share a rank card only if you are content to link that wallet to the account you post from.
Uploads are validated and rate-limited server-side. If you never press Share, this section does not apply to you.
Each of these services has its own privacy policy and its own logging practices, which are outside our control.
4. What we do not do
- No third-party analytics, no tracking across sites. There is no analytics SDK, no tracking pixels, no advertising identifiers. The only usage signal we receive is the anonymous event counting described in section 3, tied to a random install id and never to your identity or browsing.
- No accounts. There is no sign-up, no email, no password.
- No selling of data, ever. We do not sell user data, and we do not share it with third parties outside the flows this policy describes.
- No advertising, and no use of your data for advertising.
- No browsing history collection. Hover only runs on
x.comandtwitter.com, and only reads the page to detect token addresses and tickers so it can show a card. It does not read, store, or transmit your posts, messages, timeline, or account.
5. Where Hover runs
Hover's content script is restricted to x.com and twitter.com. It does not run on any other website.
6. Children
Hover is not directed to children and is not intended for anyone under 18.
7. Changes
If this policy changes materially, the updated version will be published here with a new "Last updated" date, and the extension listing will reflect it.
8. Contact
Questions about this policy: onhoverxyz@gmail.com